2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-3223 | — | — | 0.4% | Apr 22, 2013 | The ax25_recvmsg function in net/ax25/af_ax25.c in the Linux kernel before 3.9-rc7 does not initialize a certain data st... |
| CVE-2013-3222 | — | — | 0.4% | Apr 22, 2013 | The vcc_recvmsg function in net/atm/common.c in the Linux kernel before 3.9-rc7 does not initialize a certain length var... |
| CVE-2013-3076 | — | — | 0.4% | Apr 22, 2013 | The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local user... |
| CVE-2013-3221 | — | — | 2.0% | Apr 22, 2013 | The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type ... |
| CVE-2013-2780 | — | — | 2.4% | Apr 22, 2013 | Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and... |
| CVE-2013-0700 | — | — | 2.4% | Apr 22, 2013 | Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and... |
| CVE-2013-0138 | — | — | 4.8% | Apr 22, 2013 | BitZipper 2013 before Update 1 allows remote attackers to execute arbitrary code or cause a denial of service (memory co... |
| CVE-2013-0122 | — | — | 0.4% | Apr 22, 2013 | The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (applic... |
| CVE-2013-3060 | — | — | 6.3% | Apr 21, 2013 | The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain... |
| CVE-2013-3211 | — | — | 1.7% | Apr 19, 2013 | Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe i... |
| CVE-2013-3210 | — | — | 1.7% | Apr 19, 2013 | Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obt... |
| CVE-2013-3075 | — | — | 10.8% | Apr 19, 2013 | Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities... |
| CVE-2013-2697 | — | — | 1.0% | Apr 19, 2013 | Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote... |
| CVE-2013-1416 | — | — | 2.9% | Apr 19, 2013 | The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before... |
| CVE-2013-1086 | — | — | 1.2% | Apr 19, 2013 | Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows ... |
| CVE-2013-0129 | — | — | 0.8% | Apr 19, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject a... |
| CVE-2013-1199 | — | — | 0.6% | Apr 18, 2013 | Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive S... |
| CVE-2013-1194 | — | — | 1.2% | Apr 18, 2013 | The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggr... |
| CVE-2013-1177 | — | — | 1.1% | Apr 18, 2013 | SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allow... |
| CVE-2013-1176 | — | — | 1.2% | Apr 18, 2013 | The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before ... |
| CVE-2013-0139 | — | — | 1.5% | Apr 18, 2013 | The Arecont Vision AV1355DN MegaDome camera allows remote attackers to cause a denial of service (video-capture outage) ... |
| CVE-2013-0133 | — | — | 0.4% | Apr 18, 2013 | Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local us... |
| CVE-2013-0132 | — | — | 1.3% | Apr 18, 2013 | The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assi... |
| CVE-2013-1749 | — | — | 1.0% | Apr 18, 2013 | Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to ... |
| CVE-2013-1748 | — | — | 1.0% | Apr 18, 2013 | Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now